New macOS Malware 'Gaslight' Uses AI Confusion Tactics

New macOS Malware 'Gaslight' Uses AI Confusion Tactics

First seen 25 Jun 2026, 16:41 UTC Infosecurity-MagazineBleepingcomputer 84% similarity 77.0
Share:

Article Content

Browse articles
ThreatCluster

A newly identified macOS malware named 'Gaslight' has been linked to North Korean threat actors. This malware employs a unique method of embedding 38 fabricated system messages within its Rust binary to confuse AI-assisted malware analysis tools. The fake messages mimic legitimate error logs and debugging output, aiming to mislead AI systems into aborting their analysis. SentinelOne researchers attribute this malware to a growing trend where threat actors target AI tools rather than traditional sandboxes. The malware also includes backdoor and information-stealing functionalities, capable of extracting sensitive data from various browsers and the macOS keychain. Its command channel utilizes Telegram's Bot API for encrypted communication, complicating detection efforts. The findings indicate a significant evolution in malware tactics, specifically designed to exploit AI-assisted security measures.

Key Points: • The 'Gaslight' malware targets AI analysis tools with fake error messages. • It is linked to North Korean threat actors and includes backdoor capabilities. • The malware's command channel uses Telegram for encrypted communication.

ThreatCluster AI

Timeline

2026-06-24
Gaslight malware identified
SentinelOne reported the discovery of a new macOS malware that confuses AI analysis tools with fake error messages.
Infosecurity-Magazine
2026-06-25
Details of Gaslight's functionality revealed
BleepingComputer published findings on how Gaslight embeds 38 fake system messages to mislead AI analysis.
Bleepingcomputer

Community

Browse all →